On Sun, 14 Sep 2003, Magne Andreassen wrote:
> say, Manuel, have you been thinking of using pf instead of ipfilter?
> pros, cons?
Yeah... Pros? More features, more active development, faster than ipfilter
running on OpenBSD, ALTQ allows for nice queueing/prioritizing. Cons?
Slower than ipfilter on FreeBSD (with that beta FreeBSD port that is
available - though ipfilter running on FreeBSD is still faster than pf on
OpenBSD), traffic shaping with fixed bandwidth limits not as
straightforward as with ipfw/dummynet. If pf under FreeBSD were of release
quality and at least as fast as ipfilter, I'd definitely consider the
option of moving to pf.
And no, m0n0wall is not going to be ported to OpenBSD - probably ever.
- Manuel |